Alerts

Microsoft Edge Security Update – 06 June 2023

Microsoft has released an updated Edge version to fix Microsoft Edge-specific vulnerabilities, as well as chromium-based vulnerabilities. The addressed vulnerabilities could allow the remote attacker to perform various attacks such as bypassing security restrictions, gaining elevated privileges, or gaining access to the vulnerable system. Sample of the addressed vulnerabilities: 1. Microsoft Edge Privilege Escalation Vulnerability

Microsoft Edge Security Update – 06 June 2023 Read More »

MOVEit Transfer Security Update – 04 June 2023

MOVEit Transfer has released a security update to address a zero-day vulnerability. The addressed vulnerability could allow the remote attacker to gain unauthorized access to the application’s database and execute arbitrary commands, disclose information, and alter/delete database elements. the addressed vulnerability: Progress MOVEit Transfer SQL Injection Vulnerability (CVE-2023-34362): CVSS: 9.8 Attack Vector: Network Attack Complexity:

MOVEit Transfer Security Update – 04 June 2023 Read More »

Barracuda Security Update – 31 May 2023

Barracuda has released a security update to address a zero-day vulnerability across Email Security Gateway (ESG) appliances versions 5.1.3.001-9.2.0.006. The addressed vulnerabilities could allow the remote attacker to execute arbitrary code on the system with the privileges of the Email Security Gateway product by attaching a specially crafted TAR archive file in the email and gain

Barracuda Security Update – 31 May 2023 Read More »

VMware Security Updates – 31 May 2023

VMware has released security updates to fix multiple vulnerabilities across multiple Vmware products. The addressed vulnerabilities could allow the remote attacker to perform cross-site scripting attacks, or disclose sensitive information from the affected products using a specially crafted URL to redirect the victim to the attacker-controlled domain. Sample of the addressed vulnerabilities: VMware Insecure Redirect

VMware Security Updates – 31 May 2023 Read More »

Google Chrome Security Update – 31 May 2023

Google has released an updated Chrome version (114.0.5735.90/91) for Windows and (114.0.5735.90) for Linux and Mac to fix multiple vulnerabilities. Write here analysis sectionThe addressed vulnerabilities could allow the remote attacker to gain access, execute arbitrary code on the system, or bypass security restrictions by persuading the victim to visit a specially crafted webpage. Sample

Google Chrome Security Update – 31 May 2023 Read More »

Apache Security Update – 23 May 2023

Apache has released a security update to address a vulnerability in Apache Tomcat. The addressed vulnerability could allow the remote attacker to cause a denial of service by sending a specially crafted request using query string parameters. Apache Tomcat Denial of Service Vulnerability (CVE-2023-28709): CVSS: 7.5 Attack Vector: Network Attack Complexity: Low Privileges Required: None

Apache Security Update – 23 May 2023 Read More »

Apple Security Updates – 21 May 2023

Apple has released security updates to address multiple vulnerabilities across macOS Ventura, macOS Monterey, macOS Big Sur, and Safari. The mentioned updates contain fixes for three zero-day vulnerabilities. The addressed vulnerabilities could allow the attacker to gain access, escalate privileges, bypass security restrictions, obtain information, or execute arbitrary code on the affected systems. Sample of

Apple Security Updates – 21 May 2023 Read More »

Cisco Security Updates – 18 May 2023

Cisco released security updates to address several vulnerabilities affecting multiple Cisco products. The addressed vulnerabilities could allow the attacker to execute arbitrary code, gain access, bypass security restrictions, escalate privileges, obtain sensitive information, or cause a denial of service attack on the affected systems. Sample of the addressed vulnerabilities: Cisco Small Business Series Switches Buffer

Cisco Security Updates – 18 May 2023 Read More »

Trend Micro Security Updates – 17 May 2023

Trend Micro has released security updates to fix multiple vulnerabilities across Apex One and Apex Central. The addressed vulnerabilities could allow the attacker to gain access, gain elevated privileges, or obtain sensitive information from the affected products. Sample of the addressed vulnerabilities: 1. Management Server Path Traversal Unauthenticated RCE Vulnerability (CVE-2023-32557): CVSS: 9.8 Attack Vector:

Trend Micro Security Updates – 17 May 2023 Read More »

VMware Security Update – 14 May 2023

VMware has released a security update to fix multiple vulnerabilities across VMware Aria Operations (formerly vRealize Operations) and VMware Cloud Foundation. addressed vulnerabilities could allow the authenticated attacker to gain elevated privileges on the affected system by sending a specially crafted request. Sample of the addressed vulnerabilities: VMware Aria Operations Privilege Escalation (CVE-2023-20877): CVSS: 8.8

VMware Security Update – 14 May 2023 Read More »

Palo Alto Security Updates – 11 May 2023

Palo Alto has released security updates addressing vulnerabilities in multiple products. The addressed vulnerabilities could allow the attacker to store a JavaScript payload in the web interface or export local files from the firewall through a race condition. The addressed vulnerabilities: 1. Stored Cross-Site Scripting (XSS) Vulnerability in the Panorama WebInterface (CVE-2023-0007): CVSS: 6.5 Attack

Palo Alto Security Updates – 11 May 2023 Read More »

Intel Security Updates – 10 May 2023

Intel has released security updates to fix several vulnerabilities in multiple products. addressed vulnerabilities could allow the attacker to escalate privileges, obtain sensitive information, or cause a denial of service attack on the affected products. Sample of the addressed vulnerabilities: 1- Intel i915 Graphics Drivers for Linux Privilege Escalation (CVE-2023-28410): CVSS: 8.8 Attack Vector: Local

Intel Security Updates – 10 May 2023 Read More »

Citrix Security Updates – 10 May 2023

Citrix has released security updates to address several vulnerabilities in Citrix ADC and Citrix Gateway. The addressed vulnerabilities could allow the remote attacker to gain unauthorized access to the system, or perform a cross-site scripting attack to steal the victim’s cookie-based authentication credentials. The addressed vulnerabilities: 1. Citrix ADC and Gateway Unauthorized Access (CVE-2023-24487): CVSS: 6.3

Citrix Security Updates – 10 May 2023 Read More »

Mozilla FireFox Security Updates – 10 May 2023

Mozilla has released security updates to fix vulnerabilities in Firefox 113, and Firefox ESR 102.11 The addressed vulnerabilities could allow the remote attacker to gain access, obtain sensitive information, conduct a spoofing attack, bypass security restrictions, execute arbitrary code, or cause a denial of service attack on the affected products. Sample of the addressed vulnerabilities:

Mozilla FireFox Security Updates – 10 May 2023 Read More »

Microsoft May 2023 Patch Tuesday

Microsoft has released its monthly patch of security updates, known as Patch Tuesday. The mentioned patch contains a fix for three zero-day vulnerabilities. Microsoft has fixed (38) vulnerabilities, with (6) classified as critical as they could allow the attacker to perform remote code execution on the affected products. May’s Patch Tuesday was released to fix security flaws in some

Microsoft May 2023 Patch Tuesday Read More »